Reconnaissance and resource development
The reconnaissance tactic is the first step that's performed by the threat actor. It consists of collecting information on the target to prepare for the next steps.
As its name suggests, the resource development step's goal is to develop the necessary resources to perform the rest of the operations.
As we've explained previously, these tactics and their techniques are mostly used outside our organization's visibility, so difficult for a defender to do something about it. Let's look at the most commonly used reconnaissance and resource development techniques by threat actors:
- Reconnaissance:
- T1595 Active Scanning
- T1596 Search Open Technical Databases
- Resource Development:
- T1583 Acquire Infrastructure
- T1584 Compromise Infrastructure
- T1587 Develop Capabilities
- T1588 Obtain Capabilities
As we can see, except for the scanning activities, it may be almost impossible to do anything about those techniques...